CSSLTD::OPS ONLINE PROGRAMME BASTION / FORTRESS BATCH 026/2026 FIRMWARE DASHARO+HEADS / OPENPOWER MIN.ORDER 5 UNITS
UTC --:--:--
CSSLTD // DESKTOP PROGRAMME // BATCH 026

The operator's workstation.
Two tiers. Zero compromise.

The desktop equivalents of our SENTINEL laptop — hand-built sovereign workstations sold in two configurations. BASTION runs Dasharo Coreboot+Heads on a 14th-gen Intel platform with measured boot, Qubes-OS-certified hardware, and the same identity bundle, YubiKey, Tor stack, and CITADEL licence as our laptop. FORTRESS takes that further: an IBM POWER9 Talos II workstation, the only modern platform auditable to the silicon — no Intel ME, no AMD PSP, blob-free firmware down to CPU microcode. Same team package on both. Built for teams. Minimum order: 5 units.

// CSSLTD.WORKSTATION // PROVISIONING SEQUENCE //
2tiers Bastion · Fortress
9platforms pre-provisioned identities
5yr hardware warranty
£10Kcover integrity guarantee per unit
01 / Tiers

Two builds. Same package.
One honest choice.

Your team's threat model dictates which tier fits. We don't push the more expensive one. BASTION is the right answer for the vast majority of operators — it's faster, runs Qubes OS natively, and shares 95% of the security stack. FORTRESS is for teams whose threat model genuinely demands silicon-level auditability, where the cost of unaudited microcode is unacceptable.

// TIER 01 // BASTION //
BASTION
Modern x86 performance · Dasharo Coreboot + Heads · Qubes OS · the right tool for almost every operator team.
per unit · ex-VAT £95,499
  • 14th-gen Intel i9-14900 · 24C / 32T · up to 5.8 GHz · DDR5
  • Dasharo Coreboot+Heads · measured boot · YubiKey-attested integrity
  • Intel ME neutralised via HAP bit + me_cleaner
  • Qubes OS 4.2 certified hardware · iGPU only on Qubes path
  • TPM 2.0 · LUKS2 unlock bound to YubiKey + measured boot
  • Tamper-evident sealing · sealed screws · sealed transport bag
  • Same team package as FORTRESS · YubiKey · 9 identities · CITADEL · docs
// VERDICT // For 95% of teams: journalists, NGOs, security researchers, executives, lawyers handling privileged communications. Modern performance, daily-driver compatible, the same comms stack as your laptop.
// TIER 02 // FORTRESS //
FORTRESS
IBM POWER9 Talos II · the only modern workstation auditable to silicon · for teams whose threat model demands it.
per unit · ex-VAT £249,999
  • 2× IBM POWER9 Sforza · 8-core each · 16C/64T · 4-way SMT
  • Raptor CS Talos II · OpenPOWER · EATX
  • No Intel ME · No AMD PSP · ever — by silicon design
  • Blob-free firmware down to CPU microcode · audit and rebuild any part
  • OpenBMC · open-source baseboard management · operator-controlled
  • CPU-based secure boot · operator holds the signing key
  • PCIe 4.0 · 5 slots · CAPI 2.0 · DDR4 ECC · up to 2 TB RAM
  • Same team package as BASTION (note: no Qubes — Linux on PPC64LE)
// VERDICT // For teams whose threat model includes nation-state firmware implants or who require regulatory-grade auditability of every microcode update. PPC64LE limits some software (no Qubes, narrower commercial app support). Right tool for a real threat — wrong tool for "I want it because it sounds cooler".
02 / Threat Profile

Stock workstations have three open doors.

A standard pre-built PC ships with three layers of attack surface that exist by default. Both BASTION and FORTRESS close all three — they just close the silicon layer differently. Here's what each closes.

01 / SILICON

The processor inside your processor

Every modern Intel chip ships with the Management Engine. Every modern AMD chip ships with the Platform Security Processor. Both are closed-source co-processors with ring-3 access to RAM, network, and disk, alive even when the machine is "off". BASTION neutralises Intel ME via HAP. FORTRESS never had one.

02 / FIRMWARE

The vendor BIOS you can't audit

UEFI, Boot Guard, vendor firmware: closed code that decides what your hardware is allowed to run before the kernel exists. BASTION replaces it with Dasharo Coreboot + Heads — measured boot to a TPM, integrity attested by your YubiKey on every boot. FORTRESS runs OpenPOWER firmware, every line auditable.

03 / SOFTWARE

Telemetry & phone-number identity

Default Windows / macOS phone home on dozens of channels. Default messaging apps require — and broadcast — your phone number. Both tiers ship with Qubes OS or hardened Linux, no telemetry, and a 9-platform identity bundle with no phone numbers, registered over Tor.

03 / Bastion Build

BASTION. All-new components. Modern stack.

Built around a Qubes-OS-certified mainboard with 14th-gen Intel performance. Every component installed new, the case sealed with tamper-evident screws after a 48-hour burn-in, and Dasharo Coreboot+Heads flashed before the chassis is closed. Identical team package as FORTRESS.

Hardware ALL NEW

Chassis
Fractal Design Define 7 · sound-dampened NEWMid-tower · USB-C front · CSSLTD-laser-etched
Mainboard
MSI PRO Z790-P or equivalent NEWCoreboot/Dasharo-supported · TPM 2.0 header · PS/2 (for Qubes)
CPU
Intel Core i9-14900 · 24C/32T · up to 5.8 GHz NEW14th gen Raptor Lake-R · UHD 770 iGPU · 65 W base / 219 W boost
RAM
64 GB DDR5-5600 ECC · 2× 32 GB NEWKingston Server Premier · upgradable to 192 GB · 4 slots
Storage A
2 TB Samsung 990 PRO NVMe (boot) NEWPCIe 4.0 · LUKS2 · aes-xts-plain64 · YK-bound unlock
Storage B
2 TB WD Red SN700 NVMe (data) NEWseparately encrypted volume · for ops data & .onion services
Cooling
Noctua NH-U12A + 3× NF-A12x25 chromax NEWsilent operation · 24+ dBA at idle
PSU
Seasonic Prime TX-850 · 80+ TIT NEW12-year warranty · sealed in chassis
Network
Intel I225-V 2.5 GbE · onboardno proprietary firmware blob required
TPM
Discrete TPM 2.0 module NEWInfineon SLB 9670 · measured-boot anchor
I/O
4× USB-A 3.2 · 2× USB-C TB4 · 4× USB-2.0 · DP · HDMI · PS/2PS/2 for Qubes dom0 keyboard/mouse without USB passthrough
Sealing
Tamper-evident screws + sealed transport bagphotographs of seals emailed before dispatch

Software stack SIGNED

Firmware
Dasharo Coreboot 2025.x + Heads payloadmeasured boot · YK-attested integrity · 5-yr Dasharo Entry Subscription
ME state
HAP bit set · me_cleaner stub · runtime ME inertall hashes published in build attestation
Boot anchor
TPM 2.0 + YubiKey HOTP attestationgreen LED on YK = clean boot · red = tampered
OS · primary
Qubes OS 4.2 (Xen-isolated)dom0 + qubes for: work · personal · vault · sys-net · sys-firewall · sys-tor
OS · alt
Arch Hardened (CSSLTD profile)linux-hardened · AppArmor enforce · LUKS2/Argon2id · sway
Disk
LUKS2 · aes-xts-plain64 · 512-bit · Argon2idYubiKey + passphrase unlock · separate per-volume keys
Network
sys-firewall (nftables, default-drop) + sys-tor + sys-vpn (WG)qube traffic routed through Tor by default · per-qube SOCKS
Tor stack
tor + nginx-on-onion + OnionShare + SimpleX relay-hostv3 hidden service templates · ready to host out of the box
Comms
Element + CITADEL clients pre-installed in dedicated qubeisolated from work qubes · keys provisioned at handover
Auth
YubiKey 5C NFC + 5C Nano (backup)FIDO2 · PGP · PIV · sudo · login · LUKS · SSH · GPG
Reproducible
Public Ansible manifest for OS · Dasharo source for firmwareSHA-256 attestation per binary · CSSLTD-signed
No telemetry
Disabled at every layer · firewall rules block known endpointsno exceptions · audited at build time
04 / Fortress Build

FORTRESS. Audit to silicon.

Built on the IBM POWER9 Talos II — the only modern workstation platform with no Intel ME, no AMD PSP, and no closed-source firmware blobs anywhere in the boot chain. CPU microcode itself is published. Every byte from power-on to login prompt is open source. We supply, configure, and integrate the same team package as BASTION onto a fundamentally different security floor.

Hardware OPENPOWER

Chassis
Raptor CS Talos II case · sound-dampened NEWEATX · sealed · CSSLTD-laser-etched
Mainboard
Raptor Talos II · EATX · OpenPOWER NEWDDR4 ECC · 5× PCIe 4.0 · CAPI 2.0 · OpenBMC · audit-to-silicon
CPU
2× IBM POWER9 Sforza · 8-core each NEW16C/64T · 4-way SMT · 90 W TDP · published microcode
RAM
128 GB DDR4-2666 ECC RDIMM · 4× 32 GB NEWexpandable to 2 TB · 16 RDIMM slots total
Storage A
2 TB NVMe (boot) NEWPCIe 4.0 · LUKS2 · YK-bound unlock
Storage B
2× 4 TB enterprise SAS · RAID-1 (data) NEWvia Raptor SAS HBA · separate encrypted volumes
GPU
AMD Radeon Pro WX 5100 · open-firmware NEWvBIOS-free path · 8 GB · 4× DisplayPort · driver: amdgpu
Cooling
2× Raptor heatsinks + 4× Noctua NF-A12 NEWsilent · sustained 180 W cooling capacity
PSU
2× redundant 1300 W 80+ TIT NEWhot-swappable · sealed in chassis
Network
2× Broadcom BCM5719 1 GbE + Mellanox CX-5 10 GbEall firmware-free · ready for CAPI accelerators
BMC
ASpeed AST2500 + OpenBMCfully open BMC firmware · IPMI · operator-controlled
Sealing
Tamper-evident · sealed transport · DVD with schematicsRaptor ships full schematics — we extend that with our attestation

Software stack BLOB-FREE

Firmware
OpenPOWER · Hostboot + Skiboot + Petitboot100% open source · audit and rebuild every byte from source
Microcode
IBM-published POWER9 microcodeunique among modern CPUs · binary & source available
Secure boot
CPU-based secure boot · operator keyyou hold the signing key · we never see it
OS
Debian 12 PPC64LE (CSSLTD Hardened profile)linux-hardened-ppc64le · AppArmor · LUKS2 · sway
Note
Qubes OS not available on PPC64LEisolation provided via KVM-on-POWER · per-domain qemu
Disk
LUKS2 · aes-xts-plain64 · 512-bit · Argon2idYubiKey + passphrase · POWER9 hardware-accelerated AES
Tor stack
tor + nginx-on-onion + OnionShare + SimpleX relay-hostPPC64LE-native packages · same templates as BASTION
Comms
Element (PPC64LE build) + CITADEL native clientwe maintain PPC64LE builds for FORTRESS owners
Auth
YubiKey 5C NFC + 5C Nano backupFIDO2 · PGP · PIV · same as BASTION
Reproducible
Full source tree from firmware to OSunique to FORTRESS · the only x86-or-equivalent platform where this is possible
Attestation
CSSLTD-signed manifest of every binary including microcodeincluding microcode is what BASTION cannot offer
Compatibility
Native: 95% of modern Linux softwareNo Microsoft Windows · No Adobe CC · No proprietary x86-only tools
// FORTRESS HONESTY NOTICE // FORTRESS is the only desktop in this market where you can audit every line of code from power-on to login — including CPU microcode. That's a real and unique property. It's also a 2× price premium over BASTION, and it locks you to PPC64LE: no Qubes OS, no Windows dual-boot, no Adobe Creative Cloud, no x86-only proprietary apps. If your team's threat model genuinely demands silicon-level auditability — yes. If it doesn't — BASTION serves you better and saves £6,500 per operator.
05 / Firmware & Boot Integrity

Measured boot. Verified by your YubiKey.
Every boot. Every time.

BASTION ships with Dasharo Coreboot+Heads firmware, the same configuration the Qubes OS team uses in their reference builds. On every boot, Heads measures the firmware, the kernel, the initramfs, and the GRUB config into the TPM. Your YubiKey verifies the resulting hash via HOTP — green LED means clean, red LED means tampered. An evil-maid attack between the tamper-evident screws and the TPM is detectable, not theoretical.

heads.boot // CSS-D-026-A14
# --- power-on → measured boot via Heads --- ==> coreboot 2025.x SHA-256 verified ==> Heads payload SHA-256 verified ==> TPM 2.0 PCR0–PCR7 extended ==> kexec /boot/vmlinuz SHA-256 vs. signed manifest ==> initramfs verified · operator-signed ==> GRUB config verified · operator-signed heads> insert YubiKey · verify HOTP YubiKey verified · HOTP code matches. ✓ green LED on YubiKey ✓ tamper detection: clean ! intel_me: cleaned · 92% region removed (HAP set) heads> proceed to Qubes OS ==> Xen 4.17 starting ==> dom0 booting · linux-hardened 6.13 ==> LUKS2 unlock · YK + passphrase ==> sys-net · sys-firewall · sys-tor up ==> operator login ready · CSS-D-026-A14

What this actually protects against.

Honest framing: measured boot doesn't make a compromise impossible. It makes it detectable. If someone with physical access opens your tower, removes the BIOS chip, modifies it, and re-seals the case — your YubiKey will refuse to verify on the next boot. Red LED. You stop. You ship the unit back to us. We re-flash and re-attest free under the lifetime reflash policy.

  • Evil-maid attack — detected via mismatched TPM measurements + YubiKey HOTP
  • Firmware-level rootkit — can't survive the next boot's measurement check
  • Boot-chain tampering — kernel, initrd, GRUB all hashed and operator-signed
  • Stealth re-flash — physical write-protect pin is set after handover · re-flash requires opening the case · seals visibly broken
  • What it doesn't protect against — runtime exploits, supply-chain attacks before we receive the components, side-channel attacks on the silicon itself. BASTION admits its limits.
06 / Identity Bundle

Nine platforms. Same as the laptop programme.

Identical to the SENTINEL laptop bundle: nine privacy-grade platforms, registered over Tor, paid in Monero, never linked to your real identity. None require a phone number. 12-month licences renewable per-seat. Credentials handed over physically on tamper-evident paper at the same session as the workstation.

[01] EMAIL · PRIMARY
Proton Mail Visionary
e2ee · Switzerland · Tor login
Anonymous registration via Tor. Custom domain optional. Includes Proton VPN, Drive (500 GB), Calendar, Pass.
12 months · operator-named alias
[02] EMAIL · SECONDARY
Tutanota Premium
e2ee · Germany · zero-knowledge
Independent backup mailbox in a separate jurisdiction. Full-text encrypted search. No IP logs.
12 months · standalone alias
[03] VPN
Mullvad VPN
no-log · anonymous · WireGuard
Account number only. WireGuard config tied to systemd kill-switch. Cash or Monero paid.
12 months · unique account number
[04] MESSENGER · PRIMARY
Session
decentralised · onion-routed · no phone
Identity is a 66-character public key. Routes over a global node network. No phone number, no central server.
lifetime account · seed-backed
[05] MESSENGER · SECONDARY
SimpleX Chat
no identifiers · double-ratchet
No user identity at all. Connections via one-time invite links. Configured against CSSLTD-operated relay on .onion.
lifetime profile · CSSLTD relay creds
[06] MATRIX / VOICE
Element on CSSLTD homeserver
e2ee · self-hosted · federated
Operator account on hardened Synapse instance. E2EE rooms, voice, video. Federate to your own homeserver any time.
12 months · room provisioned
[07] PASSWORD MANAGER
Vaultwarden on .onion
self-hosted on the workstation itself
Your own Vaultwarden instance, hosted on the unit's .onion address. Reachable only over Tor. CSSLTD never has access.
lifetime · runs on the unit
[08] NOTES & FILES
Standard Notes Pro
e2ee · open-source clients
Encrypted notes synced across operator devices. Tagged folders, versioning, 1 TB encrypted file storage.
12 months · operator-named
[09] CITADEL COMMS
CSSLTD CITADEL
Signal Protocol · self-hosted relay
Group rooms, voice, file transfer. CSSLTD-operated relay across UK / CH / IS. Sealed-sender envelope auth.
12 months · 5 paired devices
07 / Team Documentation

Documentation written for teams,
not pamphlets.

Every team package includes a 320-page printed binder for desktop operations (longer than the laptop binder because of the additional Qubes/Tor-hosting material), the same content as cryptographically signed PDFs, and an 8-hour live onboarding programme split across two sessions over Element. Written to be operationally useful, not legally defensive.

Operator's Manual

Daily-use Qubes workflows, qube layout, identity-bundle navigation, YubiKey routine, common tasks.

PRINTED · 124 pp

Threat Model Worksheet

Per-team session. We help you map your real adversary, real assets, real failure modes for stationary infrastructure.

PRINTED · 32 pp · LIVE SESSION INC.

Incident Response Runbook

Lost · seized · compromised · power-cut · raid scenarios. Per-operator orders, in order, on the clock.

PRINTED · 56 pp · A6 LAMINATED CARDS

Recovery Procedures

Lost YubiKey, forgotten passphrase, hardware failure, drive replacement. What's recoverable, what's gone.

PRINTED · 44 pp

Team OPSEC Playbook

Group key management, shared rooms, voice protocols, file exchange, premises hardening.

PRINTED · 64 pp

Tor & Onion Cookbook

Hosting your own .onion services for the team — site, dropbox, SimpleX, Matrix homeserver, vanity addresses.

PRINTED · 48 pp

Build Attestation

Per-unit signed manifest. Every binary, every blob, every hash, every config. Proof of what we shipped.

PER UNIT · SIGNED PDF · USB

Onboarding Programme

2× 4-hour sessions over Element/CITADEL. First session: install & threat model. Second: hosting & OPSEC.

PER TEAM · 8 HOURS LIVE
08 / Order

Itemised in full. Both tiers.

Same minimum order as the laptop programme: 5 units. Same no-discount policy: every team gets the same per-unit attention. You can mix tiers within a single order — for example, three BASTION units for the analysts and two FORTRESS units for the engineers running infrastructure.

CSSLTD // BASTION // PER-UNIT 2026-05-03
BASTION hardware build · all-new componentsDefine 7 · MSI Z790 · i9-14900 · 64 GB DDR5 ECC · 4 TB NVMe (2× 2 TB) · Noctua cooling · Seasonic Prime 850W · TPM 2.0
£ 2,799
Dasharo Coreboot+Heads flash · 5-yr Entry submeasured boot · YK-attested · ME neutralised (HAP) · CSSLTD-signed SHA-256 manifest · operator USB
£ 599
Qubes OS 4.2 image · CSSLTD-hardened qubespre-configured: work · personal · vault · sys-net · sys-firewall · sys-tor · sys-vpn · sys-comms
£ 399
Tor stack & onion-hosting templatesTor daemon · stream isolation · nginx-on-onion · OnionShare · SimpleX relay · Synapse template · mkp224o
£ 249
Identity bundle · 9 platforms · 12 monthsProton Visionary · Tutanota · Mullvad · Session · SimpleX · Element · Vaultwarden · Standard Notes · CITADEL
£ 649
YubiKey 5C NFC + 5C Nano backup · operator-provisionedFIDO2 · PIV · OpenPGP · sudo · login · LUKS · SSH · GPG · provisioned in operator's presence
£ 199
Team documentation · 320-page binder + signed PDFsManual · Threat Model · IR Runbook · Recovery · OPSEC · Tor Cookbook · per-unit Build Attestation
£ 299
Live onboarding · 8-hour programme per team2× 4-hour sessions over Element / CITADEL · install + threat model + hosting + OPSEC
£ 399
QA, tamper-evident sealing, secure courier48-hour burn-in · sealed bag · couriered to named recipient · seal photographs emailed pre-dispatch
£ 249
5-year hardware warranty + lifetime reflashparts & labour · firmware updates for the unit's life
included
£10,000 compromise insurance per unitLloyd's-syndicate-underwritten · for the licence period
included
Per unit · ex-VAT
£95,499
VAT applied at point of invoice based on jurisdiction · ships UK / EU · 5–7 weeks lead time
// NO DISCOUNTS · NO TIERS · NO BULK PRICING // A BASTION takes the same hours of work whether you order five or fifty. Same attention to unit thirty as unit one.
CSSLTD // FORTRESS // PER-UNIT 2026-05-03
Talos II hardware build · OpenPOWERRaptor Talos II EATX · 2× POWER9 8-core Sforza · 128 GB DDR4 ECC · 8 TB storage · Pro WX 5100 · 2× 1300W redundant PSU
£ 8,799
OpenPOWER firmware integration & attestationHostboot/Skiboot/Petitboot built from source · operator secure-boot key generation · CSSLTD-signed manifest including microcode
£ 899
CSSLTD Hardened Debian PPC64LE imagelinux-hardened-ppc64le · AppArmor · LUKS2/Argon2id · sway · KVM-on-POWER for VM isolation
£ 499
Tor stack & onion-hosting · PPC64LE-nativesame templates as BASTION · we maintain PPC64LE builds
£ 249
Identity bundle · 9 platforms · 12 monthsidentical to BASTION · clients work natively on PPC64LE or via web
£ 649
YubiKey 5C NFC + 5C Nano backup · operator-provisionedidentical to BASTION · YubiKey works natively on PPC64LE
£ 199
Team documentation · 320-page binder + signed PDFsidentical to BASTION but with FORTRESS-specific addendum: "Living on PPC64LE"
£ 299
Live onboarding · 12-hour programme per team3× 4-hour sessions · POWER9 / OpenPOWER specifics require additional time
£ 599
QA, tamper-evident sealing, secure courier · pallet shippingEATX system requires pallet courier · seal photographs emailed pre-dispatch
£ 349
5-year hardware warranty + lifetime reflashparts & labour · firmware updates for the unit's life
included
£10,000 compromise insurance per unitLloyd's-syndicate-underwritten · for the licence period
included
Per unit · ex-VAT
£249,999
VAT applied at point of invoice based on jurisdiction · 8–10 weeks lead time (POWER9 supply-constrained)
// FORTRESS IS NICHE BY DESIGN // We will refuse FORTRESS orders we judge are based on prestige rather than threat model. The point is silicon-level audit, not bragging rights. We have BASTION for that.
// PAYMENT & LEAD TIME // 50% on order, 50% on shipment. GBP / EUR / CHF wire, or Monero / Bitcoin to a dedicated wallet. BASTION lead time: 5–7 weeks. FORTRESS lead time: 8–10 weeks (POWER9 supply-constrained). Fully refundable up to flashing-start. We respond to every team brief within 24 hours, in writing, signed.
09 / Security Guarantee

A guarantee with numbers on it.

Same terms as the SENTINEL laptop programme. Underwritten by professional indemnity insurance. Backed by SLAs. Written into the contract.

Build integrity

Every unit ships with a CSSLTD-signed manifest listing the SHA-256 of every binary, blob, and configuration file on the system. If any hash on your unit fails to match the attestation, we replace the unit and refund in full.

REPLACEMENT IN 5 BUSINESS DAYS · UK / EU
£

Compromise insurance

Each unit is covered by a £10,000 professional indemnity policy. If a security breach is forensically traced to a CSSLTD-introduced flaw — firmware, OS, or comms — the policy pays out to the operator. Underwritten by a Lloyd's syndicate.

£10,000 PER UNIT · LLOYD'S OF LONDON

Hardware warranty

Five years on every component, parts and labour, no questions about modification or firmware changes. Out-of-warranty repair continues at parts-cost for the platform's life.

5 YEARS · NO MOD-VOIDS · PARTS-COST AFTER

Lifetime reflash

If you suspect compromise, ship the unit to us. We re-flash firmware, re-image the OS, and re-issue the build attestation. Free for the life of the unit.

UNLIMITED · FREE FOR LIFE · 7-DAY TURNAROUND

No-data pact

CSSLTD does not retain operator credentials, key material, or access to provisioned identities after handover. We log no operator activity. We hold no master key, no recovery service, no backdoor.

CONTRACTUAL · AUDITABLE BY YOUR COUNSEL

Chain of custody

Tamper-evident packaging with photographed seals, signed-for delivery to the named recipient only. Each unit's serial, build hash, and courier waybill are recorded. Broken seal on arrival = unit replaced on sight.

DOCUMENTED · COURIER DIRECT · SEAL-VERIFIED
10 / Operator's Q&A

The honest answers, again.

Should I order BASTION or FORTRESS?

Default to BASTION. It's faster, cheaper, runs Qubes OS, has wider software compatibility, and shares the same identity bundle, YubiKey, Tor stack, and CITADEL licence as FORTRESS. The only reason to choose FORTRESS is if your threat model genuinely requires silicon-level firmware auditability — i.e. you cannot accept that Intel CPU microcode and FSP blobs are present in BASTION, even though they're hashed and tracked in the build attestation. For journalists, NGOs, lawyers, executives, security researchers, and the vast majority of teams, BASTION is the right answer. FORTRESS exists for a smaller cohort: governments, institutional whistleblowers, certificate authorities, regulated infrastructure operators, and a handful of teams whose adversary is the firmware-attack capability of a major nation-state.

Why is BASTION more expensive than the SENTINEL laptop?

Three reasons: (1) Modern desktop components — i9-14900, 64 GB DDR5 ECC, 4 TB of NVMe, redundant cooling, and a Qubes-certified mainboard — cost substantially more than refurbished T480 components. (2) Dasharo Coreboot+Heads requires per-board firmware engineering and an annual Entry Subscription with 3mdeb (the firmware maintainer), which we pay for on the operator's behalf for 5 years. (3) The 8-hour onboarding programme is twice as long as the laptop's 4-hour session, because Qubes OS has a steeper learning curve than a hardened single-OS setup.

Why is FORTRESS so much more expensive?

Honest answer: the IBM POWER9 platform is a low-volume product. Raptor Computing Systems' Talos II workstation lists at $11,966.99 USD before any of our team package. The motherboard alone is $2,499 USD. The CPUs are between $375 (4-core) and $2,625 (22-core) each. We use 8-core POWER9 Sforza CPUs as the right balance of cost, performance, and TDP. Add VAT, our build labour, the team package, the £10,000 insurance, and the 12-hour onboarding, and £11,999 ex-VAT is roughly cost-plus-margin — there's less room here than in BASTION. The price reflects the actual cost of an audit-to-silicon platform; if it weren't this expensive, the entire industry would be using POWER9 already.

Is "Intel ME neutralised" actually secure?

Honest answer: setting the HAP bit and running me_cleaner reduces Intel ME to a tiny boot stub that handles initial silicon bring-up and then halts. The runtime ME — the part that has ring-3 access and a network stack — is no longer executing. Independent researchers (Positive Technologies, among others) have validated this. Is it the same as not having an ME at all? No. The bring-up stub is still proprietary code. If your threat model requires zero closed-source code anywhere on the silicon, you need FORTRESS. For most threat models, neutralised ME plus measured boot plus tamper-evident sealing is the right trade.

Can I run Windows on BASTION or FORTRESS?

BASTION: yes, but we don't recommend it. The Dasharo firmware supports UEFI Secure Boot and will boot Windows 11. We can ship with a Windows-only configuration if you specifically request it (£0 price difference, but the identity bundle and Tor stack lose some integration). The Heads firmware path requires Linux. FORTRESS: no. Windows does not run on PPC64LE. There is no Windows-on-POWER9. If your team has a hard Windows dependency, FORTRESS is the wrong choice.

What about the Nitrokey NitroPC Pro 2 — isn't that the same thing?

The NitroPC Pro 2 (and NovaCustom's similar offerings) are excellent products and we respect them. They use the same Dasharo Coreboot+Heads firmware that BASTION uses, on similar 14th-gen Intel hardware. The differences are: (1) we ship as a complete team package — not just a workstation, but pre-provisioned identities, Tor hosting infrastructure, CITADEL comms, printed team documentation, 8 hours of live onboarding, and £10,000 of compromise insurance per unit. (2) We have a 5-unit minimum and a no-discount policy — we are explicitly built for teams, not individual buyers. (3) Our identity bundle and CITADEL service are CSSLTD-operated infrastructure, not just licences to third-party services. If you're a single buyer who wants the workstation only, NitroPC or NovaCustom may serve you better and cost less. If you're equipping a team and want the whole stack from one vendor, that's what we do.

Why no AMD option?

AMD's Platform Security Processor (PSP) is the equivalent of Intel ME, but cannot be neutralised the way Intel ME can — there is no equivalent of the HAP bit on AMD silicon. Coreboot support for modern AMD platforms is also significantly thinner than Intel. If we built an AMD BASTION, the PSP would still be running closed code we can't audit. We chose Intel for the desktop programme specifically because of HAP. If AMD ships a future platform with operator-controllable PSP behaviour, we'll evaluate it.

Can I host illegal services on the .onion stack you ship?

The infrastructure is operator-owned — we don't audit what you put on it. But the BASTION/FORTRESS programme is sold to teams operating within the law of their jurisdiction: journalists, security researchers, NGOs, lawyers, doctors, executives in jurisdictions with hostile threat models. We refuse orders that, in our judgement, point at criminal use. We do not ship to jurisdictions where strong encryption itself is restricted by import law.

How do I verify you didn't backdoor the unit?

Same three layers as the SENTINEL laptop programme: (1) The Dasharo firmware (BASTION) or OpenPOWER firmware (FORTRESS) are built from upstream source — we ship the build container, you re-build, the SHA-256 of the resulting image must match your unit's attestation. (2) The OS image is provisioned via a public Ansible manifest. Re-provision a unit yourself and compare every file's hash. (3) On FORTRESS specifically, you can additionally verify CPU microcode against IBM's published source — this is uniquely possible on POWER9 and impossible on any modern Intel/AMD platform.

Lead time? Where do you ship?

BASTION: 5–7 weeks from order confirmation. FORTRESS: 8–10 weeks (POWER9 supply-constrained, we order from Raptor when your deposit clears). We ship UK and EU mainland by default — pallet courier for FORTRESS due to weight, signed-for delivery to the named recipient only. For US, CH, IS, NO, and selected APAC: contact us, additional shipping & customs handling fees apply. We do not ship to jurisdictions where strong encryption or operator-controlled hardware is restricted by import law.

// BATCH 026 · ALLOCATION OPEN · 5–10 WEEK LEAD //

Equip the team's stationary infrastructure.

A 50% deposit confirms the order. The balance is taken on shipment. Refundable in full any time before flashing begins. We respond to every operator brief within 24 hours, in writing, signed.

orders@cssltd.example · PGP 0x4F2A on request · CITADEL: @ops.cssltd